ipconfig cmd not working - Geeks to Go Forums

Jump to content

Log in Register Register Malware removal guide How it works

ipconfig cmd not working windows xp

#1 Prodigal88

  • Group: Member
  • Posts: 17
  • Joined: 01-June 05

Posted 01 June 2005 - 12:40 AM

Hello all. I need to get my ipconfig cmd to work. When I type ipconfig into the cmd prompt i get the error "'ipconfig' is not recognized as an internal or external command, operable program or batch file." I have checked and ipconfig.exe is in the system32 folder. It used to work before but just suddenly stopped working recently. I have also noticed that 'ping' and 'tracert' are not working either. Do you have any idea why this migth be happening? Thank you in advance for any help you have.

Danny

#2 Guest_yezpahr_*

  • Group: Guest

Posted 01 June 2005 - 01:53 AM

Woah!!! That is certainly that new Worm (forgot the name) it deletes everything that is connected to the internet. It is probably made by a noob who wants to dominate internet by hitting people in the nuts of their computer. This worm is not deletable yet, but you could try to do the following:
if you have the installation disk of Windows at your disposal, USE IT!!
Don't make a FRESH install, just use the UPDATE service. When you have a newer version of the installed windows, it is not possible.
Go to Start -> Conrol Panel -> Add-/remove programs and select the updates.
Re-instal your windows client and probably all the internet stuff you need will be installed again. This is just specalation and I hope it helped you.
I am at school currently, typing between the checktimes of teachers. So I hope you appreciate this.

#3 Greazy

  • Group: Member
  • Posts: 277
  • Joined: 30-May 05

Posted 01 June 2005 - 01:56 AM

OUCH!! I have not heard of that one yet. Sounds like a pretty nasty little dude... Are you sure that it's not just pointing the PATH to a different location? Try this, at the command prompt, type;
PATH
Post the results here please.

Greazy Mcgeezy

#4 Metallica

  • Group: GeekU Moderator
  • Posts: 29,812
  • Joined: 23-November 04

Posted 01 June 2005 - 02:03 AM

Standardfix for the Backdoor.Win32.Rbot.pd aka P2P-Worm.Win32.Alcan.a

Please don't forget to check if the path for your system directory is correct.
Usually you will need to replace
C:\WINDOWS\system32\
with C:\WINNT\system32\ for Windows 2000
with C:\WINDOWS\system\ for windows 95, 98 and ME
with C:\WINXP\System32\ for some XP installs


*Click Here to download Killbox by Option^Explicit.
*Extract the program to your desktop and double-click on its folder, then double-click on Killbox.exe to start the program.
*In the killbox program, select the Delete on Reboot option.
*Copy the file names below to the clipboard by highlighting them and pressing Control-C:

C:\Program Files\MsConfigs\MsConfigs.exe
C:\WINDOWS\system32\p2pnetwork.exe
C:\WINDOWS\system32\CMD.COM
C:\WINDOWS\system32\netstat.com
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\tasklist.com
C:\WINDOWS\system32\taskkill.com
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\system32\tracert.com


*Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
*Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

After the reboot you will have to remove the startups for the worm, but youwill be able to use everything again.
When in doubt: http://www.geekstogo.com/forum/You_Must_Re..._Log-t2852.html

Regards,

#5 Prodigal88

  • Group: Member
  • Posts: 17
  • Joined: 01-June 05

Posted 01 June 2005 - 12:33 PM

Alright, thanks for the help. Here is results of typing PATH.

PATH=%SYSTEMROOT%\SYSTEM32;%SYSTEMROOT%;%SYSTEMROOT%\SYSTEM32\WBEM;C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL;C:\DOCUMENTS AND SETTINGS\DAN\DESKTOP\KL\
WSG32\

Im not sure if this is the correct path. If it is then I will try to remove the worm, but I'm not sure if I have the worm because I can still connect to the internet. Does the worm block your internet connection too? By the way this is on my laptop connected wirelessly if that helps at all.

ps- and yes yezpahr, i very much appreciate your help along with everyone elses. :tazz:

#6 back2killah

  • Group: Member
  • Posts: 34
  • Joined: 20-May 05

Posted 01 June 2005 - 02:03 PM

I'm not sure about this, but the last entry in your $PATH seems to be a match for WSG32, which is a spyware known as GoldenKeyLog or something like that. Very odd for a subfolder on the desktop to be added to the PATH variable.

You may want to check the HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run key in your registry and post what you see.

It definitely looks like your computer's been infected.

Perhaps someone else can confirm my suspicion.

#7 Prodigal88

  • Group: Member
  • Posts: 17
  • Joined: 01-June 05

Posted 01 June 2005 - 02:23 PM

ok, so i did the standard fix for Backdoor.Win32.Rbot.pd that metallica told me to do and that didnt work. As for back2killah's post, here is a screen shot of what i saw under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Posted Image

#8 gerryf

  • Group: Retired Staff
  • Posts: 11,365
  • Joined: 18-March 05

Posted 01 June 2005 - 02:28 PM

Prodigal, I suspect spyware---rather than attack this piecemeal, please go to the malware forum in my signature and follow the instructions at the top....Especially the CLICK HERE .

That will give you several steps that will help you clean up 70 percent of all problems by yourself. If at the end of the process you are still having difficulty, then post a hijackthis log in THAT forum.

If you are still having problems after getting a clean bill of health from the malware expert, please return to this thread.

#9 back2killah

  • Group: Member
  • Posts: 34
  • Joined: 20-May 05

Posted 01 June 2005 - 02:33 PM

Hmm, that looks pretty clean.
Do me a favor and bring up a command prompt and type "echo %systemroot%" w/o the quotes.

When I do the PATH command, the %systemroot% variable is already replaced with C:\WINDOWS in its place, so it seems odd that your path shows %systemroot% still.

#10 Prodigal88

  • Group: Member
  • Posts: 17
  • Joined: 01-June 05

Posted 01 June 2005 - 03:12 PM

back, it says C:\WINDOWS

#11 Prodigal88

  • Group: Member
  • Posts: 17
  • Joined: 01-June 05

Posted 04 June 2005 - 02:54 PM

gerryf, on Jun 1 2005, 01:28 PM, said:

Prodigal, I suspect spyware---rather than attack this piecemeal, please go to the malware forum in my signature and follow the instructions at the top....Especially the CLICK HERE .

That will give you several steps that will help you clean up 70 percent of all problems by yourself. If at the end of the process you are still having difficulty, then post a hijackthis log in THAT forum.

If you are still having problems after getting a clean bill of health from the malware expert, please return to this thread.
View Post

Well, i did everything that page said to do, nothing turned up and the commands still dont work. I posted my hijack log and explained in the malware forum but nobody replied even after a couple of bumps :tazz:

#12 gerryf

  • Group: Retired Staff
  • Posts: 11,365
  • Joined: 18-March 05

Posted 04 June 2005 - 03:33 PM

darned weird one

in the environemnt section from above, what does it say under ComSpec and windir?

#13 Prodigal88

  • Group: Member
  • Posts: 17
  • Joined: 01-June 05

Posted 04 June 2005 - 03:39 PM

environment section?

#14 gerryf

  • Group: Retired Staff
  • Posts: 11,365
  • Joined: 18-March 05

Posted 04 June 2005 - 03:43 PM

sorry....I read too quickly...I see now how you got your path statement

Right click MY COMPUTER, choose PROPERTIES< choose ADVANCED, choose ENVIRONMENT VARIABLES

#15 Prodigal88

  • Group: Member
  • Posts: 17
  • Joined: 01-June 05

Posted 04 June 2005 - 03:59 PM

ok, comspec says "C:\windows\system32\cmd.exe"
and windir says "C:\windows"

Share this topic:


  • 2 Pages +
  • 1
  • 2